Soru

Zorluk: OrtaData Privacy and Compliance Regulations

An IT technician is deploying workstation privacy filters and configuring automated screen-lock timeouts for desktop computers located in the patient check-in area of a medical facility. These systems are regularly used to view treatment schedules and diagnostic records. Which of the following compliance regulations primarily mandates these safeguards to protect Protected Health Information (PHI)?

  1. HIPAA (Health Insurance Portability and Accountability Act)Cevap
  2. B
    PCI-DSS (Payment Card Industry Data Security Standard)
  3. C
    GDPR (General Data Protection Regulation)
  4. D
    FERPA (Family Educational Rights and Privacy Act)

Cevap

HIPAA (Health Insurance Portability and Accountability Act)
HIPAA (Health Insurance Portability and Accountability Act) is the regulatory standard that governs the protection of Protected Health Information (PHI). Implementing physical controls like privacy filters and technical controls like automated screen-lock timeouts ensures compliance with HIPAA rules for workstations handling medical data.

Adım Adım Çözüm

1
Identify the data type described in the scenario
The workstation displays treatment schedules and diagnostic records, which are classified as Protected Health Information (PHI).
Determining the classification of data is required to identify the relevant privacy regulation.
2
Evaluate compliance frameworks against PHI technical and physical security requirements
HIPAA governs PHI protection and requires physical controls (privacy screens) and technical controls (auto screen locks).
Matching the administrative/technical control to the governing regulation identifies HIPAA as the required standard.

Anahtar Kavram

Data Privacy Regulations and Scope (HIPAA / PHI)
Tahmini Süre:1m 0s
Bu soruyu puanla